İçeriğe atla
Noroxi

thinksaas kayıtları

thinksaas üreticisine ait 12 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
3
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

12 kayıt
  • CVE-2020-35337
    40Planlayın

    ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows

    KritikCVSS 9,8İstismar yokEPSS %2

    thinksaas · thinksaas24 Mar 2021

  • CVE-2024-40456
    39İzleyin

    ThinkSAAS v3.7.0 was discovered to contain a SQL injection vulnerability via the name parameter at \system\action\update.php.

    KritikCVSS 9,8İstismar yokEPSS %1

    thinksaas · thinksaas16 Tem 2024

  • CVE-2019-16665
    24İzleyin

    An issue was discovered in ThinkSAAS 2.91.

    OrtaCVSS 6,1İstismar yokEPSS %1

    thinksaas · thinksaas21 Eyl 2019

  • CVE-2024-33101
    24İzleyin

    A stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrar

    OrtaCVSS 6,1İstismar yokEPSS %0

    thinksaas · thinksaas30 Nis 2024

  • CVE-2020-18741
    21İzleyin

    Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "photoid%5B%5D" and "

    OrtaCVSS 5,3İstismar yokEPSS %1

    thinksaas · thinksaas8 Tem 2021

  • CVE-2018-15129
    21İzleyin

    ThinkSAAS through 2018-07-25 has XSS via the index.php?app=article&ac=comment&ts=do content parameter.

    OrtaCVSS 5,4İstismar yokEPSS %1

    thinksaas · thinksaas7 Ağu 2018

  • CVE-2018-15130
    21İzleyin

    ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter.

    OrtaCVSS 5,4İstismar yokEPSS %1

    thinksaas · thinksaas7 Ağu 2018

  • CVE-2024-6941
    21İzleyin

    ThinkSAAS do.php cross site scripting

    OrtaCVSS 5,3İstismar yokEPSS %0

    thinksaas · thinksaas21 Tem 2024

  • CVE-2024-6942
    21İzleyin

    ThinkSAAS Admin Panel Security Center anti.php cross site scripting

    OrtaCVSS 5,3İstismar yokEPSS %0

    thinksaas · thinksaas21 Tem 2024

  • CVE-2024-33102
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attackers to execute arbitra

    OrtaCVSS 5,4İstismar yokEPSS %0

    thinksaas · thinksaas30 Nis 2024

  • CVE-2019-16664
    19İzleyin

    An issue was discovered in ThinkSAAS 2.91.

    OrtaCVSS 4,8İstismar yokEPSS %1

    thinksaas · thinksaas21 Eyl 2019

  • CVE-2024-40455
    10İzleyin

    An arbitrary file deletion vulnerability in ThinkSAAS v3.7 allows attackers to delete arbitrary files via a crafted request.

    DüşükCVSS 2,7İstismar yokEPSS %0

    thinksaas · thinksaas16 Tem 2024